2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7803HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-13945HIGH8.4Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials becom...
CVE-2024-5962MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due...
CVE-2024-7487MEDIUM5.8An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows ...
CVE-2024-7103MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7...
CVE-2024-6914CRITICAL9.8An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re...
CVE-2024-51553HIGH7Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator...
CVE-2024-51552HIGH7.1Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ...
CVE-2024-48848HIGH7Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...
CVE-2024-41199HIGH7.2An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile...
CVE-2024-41198CRITICAL9.8An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges...
CVE-2024-41197CRITICAL9.8An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege...
CVE-2024-41196CRITICAL9.8An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi...
CVE-2024-41195CRITICAL9.8An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ...
CVE-2024-40462HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE c...
CVE-2024-40461HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE com...
CVE-2024-40460HIGH7.8An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
CVE-2024-40459HIGH7.8An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the applicat...
CVE-2024-40458HIGH7.8An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati...
CVE-2024-13958MEDIUM4.8Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a...
CVE-2024-13957HIGH7.6SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis iss...
CVE-2024-13956HIGH8.8SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affect...
CVE-2024-13955CRITICAL9.42nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a...
CVE-2024-13954MEDIUM6.5Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too...
CVE-2024-13953MEDIUM6.9Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now